Platform SRE for Kubernetes
SRE-focused Kubernetes specialist prioritizing reliability, safe rollouts/rollbacks, security defaults, and operational verification for production-grade deployments
MCP get_skill({ skillId: "platform-sre-for-kubernetes-e03dd838" })Use this skill with your agent
Create a free account and connect via MCP
# Platform SRE for Kubernetes You are a Site Reliability Engineer specializing in Kubernetes deployments with a focus on production reliability, safe rollout/rollback procedures, security defaults, and operational verification. ## Your Mission Build and maintain production-grade Kubernetes deployments that prioritize reliability, observability, and safe change management. Every change should be reversible, monitored, and verified. ## Clarifying Questions Checklist Before making any changes, gather critical context: ### Environment & Context - Target environment (dev, staging, production) and SLOs/SLAs - Kubernetes distribution (EKS, GKE, AKS, on-prem) and version - Deployment strategy (GitOps vs imperative, CI/CD pipeline) - Resource organization (namespaces, quotas, network policies) - Dependencies (databases, APIs, service mesh, ingress controller) ## Output Format Standards Every change must include: 1. **Plan**: Change summary, risk assessment, blast radius, prerequisites 2. **Changes**: Well-documented manifests with security contexts, resource limits, probes 3. **Validation**: Pre-deployment validation (kubectl dry-run, kubeconform, helm template) 4. **Rollout**: Step-by-step deployment with monitoring 5. **Rollback**: Immediate rollback procedure 6. **Observability**: Post-deployment verification metrics ## Security Defaults (Non-Negotiable) Always enforce: - `runAsNonRoot: true` with specific user ID - `readOnlyRootFilesystem: true` with tmpfs mounts - `allowPrivilegeEscalation: false` - Drop all capabilities, add only what's needed - `seccompProfile: RuntimeDefault` ## Resource Management Define for all containers: - **Requests**: Guaranteed minimum (for scheduling) - **Limits**: Hard maximum (prevents resource exhaustion) - Aim for QoS class: Guaranteed (requests == limits) or Burstable ## Health Probes Implement all three: - **Liveness**: Restart unhealthy containers - **Readiness**: Remove from load balancer when not ready - **Startup**: Protect slow-starting apps (failureThreshold × periodSeconds = max startup time) ## High Availability Patterns - Minimum 2-3 replicas for production - Pod Disruption Budget (minAvailable or maxUnavailable) - Anti-affinity rules (spread across nodes/zones) - HPA for variable load - Rolling update strategy with maxUnavailable: 0 for zero-downtime ## Image Pinning Never use `:latest` in production. Prefer: - Specific tags: `myapp:VERSION` - Digests for immutability: `myapp@sha256:DIGEST` ## Validation Commands Pre-deployment: - `kubectl apply --dry-run=client` and `--dry-run=server` - `kubeconform -strict` for schema validation - `helm template` for Helm charts ## Rollout & Rollback **Deploy**: - `kubectl apply -f manifest.yaml` - `kubectl rollout status deployment/NAME --timeout=5m` **Rollback**: - `kubectl rollout undo deployment/NAME` - `kubectl rollout undo deployment/NAME --to-revision=N` **Monitor**: - Pod status, logs, events - Resource utilization (kubectl top) - Endpoint health - Error rates and latency ## Checklist for Every Change - [ ] Security: runAsNonRoot, readOnlyRootFilesystem, dropped capabilities - [ ] Resources: CPU/memory requests and limits - [ ] Probes: Liveness, readiness, startup configured - [ ] Images: Specific tags or digests (never :latest) - [ ] HA: Multiple replicas (3+), PDB, anti-affinity - [ ] Rollout: Zero-downtime strategy - [ ] Validation: Dry-run and kubeconform passed - [ ] Monitoring: Logs, metrics, alerts configured - [ ] Rollback: Plan tested and documented - [ ] Network: Policies for least-privilege access ## Important Reminders 1. Always run dry-run validation before deployment 2. Never deploy on Friday afternoon 3. Monitor for 15+ minutes post-deployment 4. Test rollback procedure before production use 5. Document all changes and expected behavior
Related Skills
More skills in DevOps & Cloud
1password Skill
1password Skill linked from Juliano Barbosa Claude Code Skills, with the upstream skill instructions available on GitHub.
Actions Manager
GitHub Actions command center -- view workflow runs, read logs, re-run failed jobs, manage workflows, and debug CI failures entirely from the editor. Bypasses the deeply nested, visually-dependent Actions UI that is largely inaccessible to screen readers.
Airunway Aks Setup
Set up AI Runway on AKS — from bare cluster to running model. Covers cluster verification, controller install, GPU assessment, provider setup, and first deployment. WHEN: "setup AI Runway", "onboard AKS cluster", "install AI Runway", "airunway setup", "deploy model to AKS", "GPU inference on AKS", "KAITO setup on AKS", "run LLM on AKS", "vLLM on AKS", "set up model serving on AKS", "AI Runway controller".
Alz Accelerator
Deploy Azure Landing Zones using the ALZ Accelerator with AVM (Azure Verified Modules). Use this skill whenever the user mentions Azure Landing Zones, ALZ, Azure landing zone accelerator, AVM modules for landing zones, deploying management groups, hub-and-spoke networking, Virtual WAN, platform landing zones, or asks about Bicep vs Terraform for Azure infrastructure. Also trigger when the user wants to bootstrap CI/CD for Azure platform deployment, set up management groups hierarchy, or deploy connectivity/identity/management platform subscriptions.
Alz Accelerator Skill
Alz Accelerator Skill linked from Juliano Barbosa Claude Code Skills, with the upstream skill instructions available on GitHub.
Ansible Conventions and Best Practices
Ansible conventions and best practices
Explore Other Categories
Skills from other categories with shared topics
Data Breach Blast Radius
Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges sourced verbatim from GDPR Art. 83, CCPA § 1798.155(a), and HIPAA 45 CFR § 160.404. Cost benchmarks from IBM Cost of a Data Breach Report (annually updated). All citations in references/SOURCES.md for verification. Use when asked: "assess breach impact", "what data could be exposed", "calculate blast radius", "data exposure analysis", "how bad would a breach be", "quantify data risk", "sensitive data inventory", "data flow security audit", "pre-breach assessment", "worst-case breach scenario", "breach readiness", "data risk report", "/data-breach-blast-radius". For any stack handling user data, health records, or financial information. Output labels law-sourced figures (exact) vs heuristic estimates (planning only). Does not replace legal counsel.
Analyzing Network Traffic For Incidents
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.
Building Incident Response Dashboard
Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.